IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Development Package for Apache Spark

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Version 8.0 that is used by IBM Development Package for Apache Spark. These issues are disclosed as part of the IBM Java SDK updates in January 2017. If you run your own Java code using the IBM Java Runtime delivered with this product, you should evaluate your code to determine whether the complete list of vulnerabilities are applicable to your code. For a complete list of vulnerabilities please refer to the link for “IBM Java SDK Security Bulletin” located in the “

CVE(s): CVE-2016-2183, CVE-2016-5546, CVE-2016-5547, CVE-2016-5548, CVE-2016-5549, CVE-2016-5552

Affected product(s) and affected version(s):

IBM Development Package for Apache Spark, v1.6.3.0, and earlier versions; or
IBM Development Package for Apache Spark, v2.1.0.0, and earlier versions

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2mit49c
X-Force Database: http://ift.tt/2dR3VyC
X-Force Database: http://ift.tt/2lA4akm
X-Force Database: http://ift.tt/2msBF5I
X-Force Database: http://ift.tt/2lAx183
X-Force Database: http://ift.tt/2msD77U
X-Force Database: http://ift.tt/2lAiqcB

The post IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Development Package for Apache Spark appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2miDmpP